#1142035 perl: CVE-2026-57433

Package:
perl
Source:
perl
Description:
Larry Wall's Practical Extraction and Report Language
Submitter:
Salvatore Bonaccorso
Date:
2026-09-02 21:19:06 UTC
Severity:
normal
Tags:
#1142035#5
Date:
2026-07-14 06:50:40 UTC
From:
To:
Hi,

The following vulnerability was published for perl.

CVE-2026-57433[0]:
| Storable versions before 3.41 for Perl have a signed integer
| overflow when deserializing a crafted SX_HOOK record.
| retrieve_hook_common reads a signed 32-bit item count from an
| SX_HOOK record and calls av_extend with that count plus one. A count
| of I32_MAX wraps the addition to a negative value.  A crafted blob
| passed to thaw or retrieve triggers the overflow; av_extend receives
| the negative count and dies with a panic, terminating the
| deserialization.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-57433
https://www.cve.org/CVERecord?id=CVE-2026-57433
[1] https://lists.security.metacpan.org/cve-announce/msg/41780100/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142035#10
Date:
2026-07-14 08:06:32 UTC
From:
To:
Control: retitle 1138906 perl: CVE-2026-57433: Storable signed integer overflow
Control: forcemerge 1138906 -1
so far.)

So merging.

Salvatore: This didn't have a CVE number earlier. Would you like me to
retroactively add one to d/changelog in a future upload?

#1142035#35
Date:
2026-07-14 19:56:28 UTC
From:
To:
Hi Niko,

Ups, apologies for that!

It is fine, not strictly needed. I made sure to fix the metadata in
the security-tracker now.

Regards,
Salvatore

#1142035#42
Date:
2026-09-02 21:17:09 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138906@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Niko Tyni <ntyni@debian.org> (supplier of updated perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 30 Aug 2026 11:53:55 +0300
Source: perl
Architecture: source
Version: 5.40.1-6+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Niko Tyni <ntyni@debian.org>
Changed-By: Niko Tyni <ntyni@debian.org>
Closes: 1137345 1138854 1138855 1138856 1138858 1138859 1138860 1138863 1138905 1138906 1140152 1141639 1142037
Changes:
 perl (5.40.1-6+deb13u1) trixie; urgency=medium
 .
   * [SECURITY] various upstream fixes:
     + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.
         (Closes: #1141639)
     + CVE-2026-42496: Archive::Tar symlink extraction.
         (Closes: #1138860)
     + CVE-2026-42497: Archive::Tar hardlink extraction.
         (Closes: #1138859)
     + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.
         (Closes: #1140152)
     + CVE-2026-13221: silently incorrect regular expression matches.
         (Closes: #1142037)
     + CVE-2025-15649: header parsing in IO::Uncompress::Unzip.
         (Closes: #1138863)
     + CVE-2026-7010:  CRLF-validation in HTTP::Tiny.
         (Closes: #1138858)
     + CVE-2026-8376:  Buffer overflow in Perl_study_chunk.
         (Closes: #1137345)
     + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.
         (Closes: #1138856)
     + CVE-2026-48961: crash in zipdetails.
         (Closes: #1138855)
     + CVE-2026-48962: code execution in IO-Compress via output globs.
         (Closes: #1138854)
     + CVE-2026-57432: out of bound heap reads in pack() and unpack().
          (Closes: #1138905)
     + CVE-2026-57433: signed integer overflow in Storable.
          (Closes: #1138906)
Checksums-Sha1:
 735f1a33e381a4037b22f895726d2ffce281b39a 2404 perl_5.40.1-6+deb13u1.dsc
 1c181a089b69ccda8f7adce847dd5d8984e247a7 186360 perl_5.40.1-6+deb13u1.debian.tar.xz
 ea71ff39ab625af81797eabf49136bbde5cba4d6 5370 perl_5.40.1-6+deb13u1_source.buildinfo
Checksums-Sha256:
 92d1cfb32167d77fada7284f1c291de72f93eb896f5cfd58247d020182b403a8 2404 perl_5.40.1-6+deb13u1.dsc
 5ee76db601d6f4638433ab9b0f5bd5cfb15b102a79d902ff282e762becb7e724 186360 perl_5.40.1-6+deb13u1.debian.tar.xz
 1d89f7d92719f484d03265fcb34f83604a133e8881dd316e5d0f3d5f123fc556 5370 perl_5.40.1-6+deb13u1_source.buildinfo
Files:
 7a19d8c54c89ea059a709d4aaa11ddef 2404 perl standard perl_5.40.1-6+deb13u1.dsc
 25a497217f31c1bd9abec448d442a144 186360 perl standard perl_5.40.1-6+deb13u1.debian.tar.xz
 d4d9e67ab46dd7c539b74461b14e7aa5 5370 perl standard perl_5.40.1-6+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iKcEARMJAC8WIQTuZv2Xfg2x/uVxefeK/rNkDrE5sgUCaphfzREcbnR5bmlAZGVi
aWFuLm9yZwAKCRCK/rNkDrE5sgacAYCoZbN23QhO+v2JfNcanwF/DXR/IxDBIVbz
wr0rQgPWbzmq5KXCXgA4BZ/Wp5+unkQBf1v9bOahz673IgWB1C/XGwZ7jUDHEVcJ
yxs3NFuIerDHvhsPIkaDw83nFiQsm/BdeQ==
=xXL0
-----END PGP SIGNATURE-----